CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.
Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.
I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency



I will take things that never should be connected to Internet for $200 Alex.
Right. Why would you do this? Monitoring being available on the Intranet, of course. But controllers on the open internet?
Might as well really focus on ease of use and just make a live website with one big button that says “cut off all electricity and turn all the water into poison, lol”
And guarded by default passwords
And the user support AI the website automatically opens in in popup can just tell you if you tell it you’re the King of Water and you forgot the account info.
It is also very easy to airgap monitoring.
Remote monitoring? Sure. Remote managing? Fuck that. These facilities shouldn’t be unstaffed for days at a time.
Oh for sure, air gapped sensors that relay information are going to be necessary. We should be building these systems with absolute security because they are critical to infrastructure.
Some people will say it’s too hard to retrofit onto legacy equipment, but all it really means is adding a secondary system on top of the legacy system. Just a sensor array that has no interaction with existing systems.
Yup. Fancy architecture diagram:
One Way Radio Transmitter [Nuclear Reactor] ------------> [Internet connected receiver] -> tHe ClOUdIt’s called paying people to watch the systems during off-hours. It’s often way cheaper than setting up firewalls, setting up alerts, maintaining patches, paying a VPN company to manage connections, paying another company to handle authentication, and so on. Security constraints are getting so bad at my office I’m seriously thinking of how we can do more things with pen and paper.
A simple 300 bps connection over POTS to relay the information from the process controller is all you need. But even POTS is disappearing.
Exactly! Whenever I see one of these stories of a utility being hacked that’s my first thought.